Network Security Solution Architect - Azure Virtual WAN (VWAN)
Calgary, Alberta, CanadaContractPosted Jun 10, 2026
Job description
Job Title: Network Security Solution Architect | Azure VWAN, Firewall, DMZ, Cloud Security & Network Architecture Role: Network Security (Solution Architect) Duration: 12 Months Work Model: Hybrid (3 days/week in office) Key Responsibilities
- Analyze current DMZ architecture, firewall rules, and security controls.
- Assist in planning and executing the migration of servers and applications into a new or redesigned DMZ.
- Identify and mitigate risks associated with exposing services to external networks.
- Validate secure configurations during migration (network segmentation, access control, routing).
- Design and enforce network segmentation strategies between DMZ, internal, and external zones.
- Review and implement firewall policies (e.g., Palo Alto, Versa Networks).
- Configure and validate NAT, ACLs, VPNs, and load balancers.
- Ensure secure communication between tiers (web, app, database).
- Assess existing firewall rules and eliminate redundant or risky rules.
- Create least-privilege access rules for new DMZ architecture.
- Perform rule recertification and documentation.
- Maintain detailed documentation of:
- Network diagrams (current and future state)
- Firewall rule sets
- Security controls implemented
- Provide migration runbooks and rollback plans.
- Lead end-to-end architecture design and governance for migration from Hub-and-Spoke to Azure VWAN, ensuring alignment with enterprise cloud and security standards.
- Define and implement application-centric migration strategies, ensuring complete application stacks (DMZ and internal dependencies) are migrated together.
- Design and oversee transit firewall decommissioning to reduce routing complexity, latency, and operational overhead.
- Lead Web Application Firewall (WAF) compliance implementation in Azure for all internet-facing applications.
- Define and execute roadmap to decommission legacy Hub-and-Spoke architecture and transition fully to VWAN.
- Drive network architecture design, including:
- Routing
- UDR optimization
- Traffic flows
- Micro-segmentation within VWAN
- Oversee firewall policy redesign and migration, ensuring secure connectivity between DMZ and internal environments.
- Perform application dependency analysis across DMZ and internal systems to minimize latency and ensure seamless functionality.
- Define migration patterns and playbooks, including:
- Re-IP strategies
- Domain migration
- Service accounts
- Cutover strategies
- Provide hands-on architectural support during migration execution, including troubleshooting, validation, and real-time decision-making.
- Collaborate with Cloud, Network, Security, Infrastructure, and Application teams for coordinated delivery.
- Identify and mitigate risks related to:
- Shared databases
- Cross-network dependencies
- Performance constraints
- Establish and enforce architecture governance, standards, and reusable design patterns.
- Support migration activities across EST and MST time zones, including critical migration windows.
- Present architecture decisions and migration impacts to senior stakeholders, translating technical concepts into business insights.